mc idp ldap accesskey ls

The mc idp ldap accesskey ls displays a list of LDAP access key pairs.

mc idp ldap accesskey ls is also known as mc idp ldap accesskey list.

This command works against access keys created by an AD/LDAP user after authenticating to AIStor.

Create AD/LDAP service accounts with the mc idp ldap accesskey create command.

Authenticated users can manage their own long-term Access Keys using the AIStor Console. AIStor supports using AssumeRoleWithLDAPIdentity to generate temporary access keys using the Security Token Service.

Syntax

Parameters

ALIAS

Required

The alias of the AIStor deployment configured for AD/LDAP.

For example:

mc idp ldap accesskey ls minio

--all

Optional

List all access keys for all LDAP users.

--self

Optional

List access keys for the currently authenticated user.

--svcacc-only

Optional

Output only service account access keys.

Mutually exclusive with --temp-only.

--temp-only

Optional

Output only temporary access keys.

Mutually exclusive with --svcacc-only.

--users-only

Optional

Output only the user distinguished names.

Examples

List All Access Keys

To return a list of all access keys, you must first authenticate as the admin user. Once authenticated, the following command returns all AD/LDAP access keys on the minio deployment.

mc idp ldap accesskey ls minio

If the user does not have the admin:ListUsers permission, the command returns a list of access keys for the authenticated user only.

List User Distinguished Names

To return a list of DNs for a deployment, you must first authenticate as a user with the admin:ListUsers permission. Once authenticated, the following command outputs the AD/LDAP distinguished names on the minio deployment.

mc idp ldap accesskey ls minio --users-only

List Temporary Access Keys

To return a list of all temporary access keys for a deployment, you must first authenticate as a user with the admin:ListUsers permission. Once authenticated, the following command outputs a list of distinguished names with their associated temporary access keys.

mc idp ldap accesskey ls minio --temp-only

List a User’s Access Keys

The following command returns the AD/LDAP access keys for the user bobfisher on the minio deployment.

mc idp ldap accesskey list minio/ uid=bobfisher,dc=min,dc=io

List Access Keys for Multiple Users

The following command returns the AD/LDAP access keys for the users bobfisher and cody3 on the minio deployment.

mc idp ldap accesskey list minio/ uid=bobfisher,dc=min,dc=io uid=cody3,dc=min,dc=io

List Access Keys for Authenticated User

The following command returns the AD/LDAP access keys for the currently authenticated user on the minio deployment.

mc idp ldap accesskey list minio/

If the authenticated user has the admin:ListUsers permission, the command returns a list of all users and access keys on the deployment.

Global Flags

This command supports any of the global flags.

Behavior

S3 Compatibility

The mc commandline tool is built for compatibility with the AWS S3 API and is tested with AIStor and AWS S3 for expected functionality and behavior.

AIStor provides no guarantees for other S3-compatible services, As their S3 API implementation is unknown and therefore unsupported.

While mc commands may work as documented, any such usage is at your own risk.